CVE-2017-17681
HIGH 7.1EPSS 3.0%
In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted psd image file.
- CVSS v3.0
- 6.5 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - CVSS v2.0
- 7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C - EPSS
- 2.97% chance of exploitation in the next 30 days, 86th percentile
- Published
- 2017-12-14
- Updated
- 2024-08-05